VYPR
Unrated severityNVD Advisory· Published Aug 20, 2019· Updated Sep 17, 2024

CVE-2019-4310

CVE-2019-4310

Description

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Guardium Big Data Intelligence 4.0 has an inadequate account lockout setting, allowing remote attackers to brute force account credentials.

Vulnerability

IBM Security Guardium Big Data Intelligence (SonarG) version 4.0 uses an inadequate account lockout setting that fails to limit the number of failed authentication attempts. This allows an attacker to repeatedly attempt login without being locked out. The vulnerability is present in the default configuration of the affected version.

Exploitation

An attacker with network access to the Guardium Big Data Intelligence service can perform a brute-force attack against user accounts. No authentication or user interaction is required. The attacker can systematically attempt passwords until the correct one is found, as the system does not enforce account lockout after a threshold of failed attempts.

Impact

Successful exploitation allows the attacker to gain access to a valid user account, potentially leading to the disclosure of sensitive information. According to the CVSS vector (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the impact is primarily on confidentiality, with high severity.

Mitigation

IBM has published a security bulletin (reference [1]) addressing this vulnerability. The recommended mitigation is to apply the fix provided by IBM, which may involve upgrading to a patched version or adjusting account lockout settings. The exact fixed version or configuration details are not specified in the available references. Users should consult the IBM support page for the latest guidance.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.